CVE-2013-3346
KEVmassMemory Corruption RCE in Adobe Reader and Acrobat
CISA: Adobe Reader and Acrobat Memory Corruption Vulnerability
Adobe Reader and Acrobat contain a memory corruption vulnerability (CWE-119, buffer/pointer handling error) that can allow an attacker to execute arbitrary code or crash the application. The bug is triggered by processing maliciously crafted content, typically when a user opens a booby-trapped PDF document. Successful exploitation yields arbitrary code execution with the privileges of the logged-in user, while failed exploitation can cause a denial of service. Anyone running affected Adobe Reader or Acrobat installations is exposed, with desktop users who open PDFs from email or the web at greatest risk. The flaw has been exploited in the wild: CISA added it to the KEV catalog on 2022-03-03 and it carries a very high EPSS score of 78.6%, although no public proof-of-concept is known.
What to do: Apply vendor-supplied updates to Adobe Reader and Acrobat immediately, per the Adobe security bulletin and the CISA KEV required action, and retire or upgrade legacy unpatched builds that are past end of support. Because exploitation requires a user to open a crafted PDF, inspect or sandbox PDFs at email and web gateways and hunt for signs of PDF exploit delivery; treat this flaw as actively exploited given the KEV listing and 78.6% EPSS.
| Adobe Reader | — |
| Adobe Acrobat | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.
- Affected
- Adobe Reader and Acrobat
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Reader and Acrobat
- Weakness
- CWE-119